Get Assessment-Ready for CMMC Before You Pay an Assessor.
Small defense subcontractors in Connecticut are getting flow-down letters from their primes and have no idea where they stand. We do the readiness work: find the gaps, fix them, write the documents, and organize the evidence. Then you walk into a Level 2 assessment prepared instead of paying to fail it.
Where things stand right now
- Nov 10, 2025In effect
CMMC Phase 1 began. Level 1 and Level 2 self-assessments, with a score posted to SPRS, are required in new DoD contracts.
- Jul 13, 2026Paused
The Department of War suspended Phase 2 (third-party Level 2 certification, scheduled for Nov 10, 2026) and opened a 60-day reform review.
- TodayStill required
DFARS 252.204-7012 and NIST SP 800-171 apply to every contract that touches Controlled Unclassified Information. Your prime can ask for your SPRS score and your System Security Plan tomorrow.
Why the pause is good news for you
Getting a shop through a third-party Level 2 assessment with a large compliance firm routinely runs into six figures, and assessors bill for every hour, including the hours spent documenting what you got wrong. Nobody knows exactly when the certification requirement returns. What we do know is that the 110 controls will not disappear. Getting them in place now, at a small shop's pace and price, is the cheapest path there is.
CMMC in plain English
What it is
CMMC is the Department of Defense’s way of checking that contractors actually follow the NIST SP 800-171 security rules they have been agreeing to since 2017. Level 1 covers 17 basic practices for Federal Contract Information. Level 2 covers all 110 controls of NIST SP 800-171 and applies to anyone who handles Controlled Unclassified Information (CUI): drawings, specs, test data, anything marked or flowed down from a DoD program.
What a flow-down letter means
When a prime sends you a letter asking for your SPRS score, your CMMC level, or a copy of your SSP, they are deciding whether you stay on the approved supplier list. A missing or low score is a reason to move the work to a shop that has one.
What an SPRS score is
You score yourself against the 110 controls, starting at 110 and subtracting points for each one you do not meet (some cost 1, some 3, some 5). Scores can go negative. You post that number to the Supplier Performance Risk System and certify it is accurate. A false score is a False Claims Act problem, so guessing is not a strategy.
Where most small shops stand today
Sound familiar? You are not alone. Every shop we assess starts with most of these. None of them are unusual. All of them are fixable.
Illustrative. Your starting score is whatever the truth is, and the first thing we do is find out.
What we do: readiness, not certification
We are not an assessor and we do not issue certificates. Our job is to make sure that when you do hire one, the assessment is a formality.
Gap assessment and honest SPRS score
We review all 110 controls against your actual environment, on site, and give you a real score with a written list of what is missing. Free written summary; you keep it either way.
System Security Plan and POA&M
The two documents every prime and every assessor asks for first. Written for your shop, in plain language, describing how you actually operate.
Technical controls
MFA everywhere it belongs. Managed endpoint protection on every machine. Centralized logging with retention. Access control that matches job roles. Patching that runs. Backups that are verified. Windows 10 retired.
Policies and people
Acceptable use policy signed by every employee, onboarding and offboarding procedures, phishing awareness through an online training platform, and one-on-one help for the owner on what the rules mean day to day.
Evidence, organized
Assessors want proof, not promises. We collect screenshots, configs, logs, and signed documents into an evidence package mapped to each control so nobody is digging through folders during the assessment.
Keep it true
Compliance drifts the week after you achieve it. Ongoing monitoring, monthly reporting, and a fixed point of contact keep the controls in place between assessments.
Readiness first saves real money
CMMC hardening at a large compliance firm is expensive. That is not a knock on them; it is the market. Enterprise-scale consultants, project managers, and hourly rates built for companies with a hundred seats. A 12-person shop pays the same rate card.
Then the assessment itself. Connecticut firms that take shops through Level 2 certification quote well into six figures for the full project, and if you walk in with open findings you pay for the findings, pay to fix them, and then pay for the re-assessment.
Every shop is different, so we quote after the gap assessment, in writing, before any work starts. What we can say up front: our rates are a fraction of what regional compliance firms charge, and there is no retainer. The money you save on readiness is money you still have when the assessor's invoice arrives.
| Unprepared | Large firm | CT Tech Express | |
|---|---|---|---|
| Who does the work | You, between jobs | Consultant team, remote | One technician, on site |
| Rate structure | n/a | Enterprise hourly or retainer | Small-shop hourly, month to month, no retainer |
| Result at assessment | Open findings, re-assessment | Ready | Ready |
| Assessor hours spent on your gaps | Many | Few | Few |
| Support after the assessment | None | Separate contract | Same person, same rates |
What we don't do, and who does
We do not
- Issue CMMC certificates. Only a DoD-authorized C3PAO can.
- Guarantee you will pass. We get you to the point where passing is the expected outcome, and we show you the evidence before you book the assessment.
- Sell you a “compliance in a box” you do not understand. You will know what every control does and why.
When you are ready
- We work directly with a Connecticut managed IT firm that holds its own CMMC Level 2 certification, for shops that need a certified provider to take on part of their in-scope environment, and we can introduce you to a Connecticut C3PAO for the assessment itself.
- We stay involved through the assessment: answering the assessor’s questions, pulling evidence, and fixing anything they flag.
Case study: a central Connecticut test and engineering firm
The situation
About 20 endpoints and a small server rack. Engineering and test data covered by DFARS 7012 sitting on a shared file server. Handshake-level IT, no logging, no signed policies, and a prime starting to ask questions.
What we put in place
- Self-hosted SIEM on their own hardware, so security telemetry never leaves the building. Every workstation and server reporting.
- File-level auditing on the CUI folders: every read, copy, and delete logged with the user and workstation, with alerts for bulk copying and after-hours access.
- Three-year tamper-evident log retention off site, encrypted, with a monthly report the owners sign off on.
- File server permissions rebuilt so employees can read and add, and only the owners can change or delete.
- Application allow-listing rolled out in audit mode to control what software can run.
- Acceptable use policy e-signed by all staff, with an annual re-sign.
- Managed antivirus, patching, verified backups, and a monthly IT health report on every machine.
Client name withheld at their request. References available for serious inquiries.
Frequently asked questions
We only have six people. Does this really apply to us?
If you handle CUI under a DoD contract or subcontract, yes. Size does not exempt you. It does make you cheaper to fix.
Can we just self-assess and post a score?
For Level 1, yes. For Level 2 today, self-assessment is what is required, but the score has to be honest and a company officer affirms it. Posting 110 when you are at 40 is a legal problem, not a shortcut.
What is CUI, exactly?
Controlled Unclassified Information: unclassified data the government says must be protected. For a supplier that is usually drawings, specs, test reports, and anything marked CUI or flowed down from a program. If you are unsure what you have, that is the first thing we sort out.
How long does readiness take?
It depends on the starting point. A shop with a handful of machines and cooperative owners can be in good shape in a few months. Documents and evidence take as long as the technical work.
What will it cost?
We quote after the gap assessment, in writing, before any work starts. Our rates are well below regional compliance firms and there is no retainer.
Do we need a separate “enclave” for CUI?
Sometimes. Isolating the few machines that touch CUI can shrink what the assessor has to look at and cut cost. We will tell you if it makes sense for your shop.
What about the Phase 2 suspension? Should we wait?
The controls did not change and your contracts still require them. Waiting means doing the same work later, faster, under a deadline. Doing it now at your own pace is cheaper.
Do you handle everything, or do we need other vendors?
We handle the readiness work end to end. The assessment itself is done by an independent C3PAO, and for shops that need a certified provider to run part of their environment we bring in a Connecticut partner that holds Level 2 certification.
Find out where you stand before your prime asks.
Free on-site gap assessment with a written summary. No retainer, no long-term contract.
CT Tech Express is an independent IT provider. We are not a C3PAO and do not issue CMMC certifications.
